Avoid crashing when localhost attempts to trigger COOP isolation.

ChildProcessSecurityPolicyImpl::AddIsolatedOriginForBrowsingInstance()
assumes that it only ever seems valid isolated origins and uses a
CHECK to enforce this.  Callers of this function that use legacy
isolated origins (i.e., not Origin-Agent-Cluster) are expected to
check IsolatedOriginUtil::IsValidIsolatedOrigin() on the origin being
isolated prior to calling this.

Android's COOP-triggered site isolation mode (controlled by
features::kSiteIsolationForCrossOriginOpenerPolicy, enabled by default
in M95) has a couple of code paths that lead to calling this function.
After seeing a user gesture, it uses SiteInstance::StartIsolatingSite,
which has a IsValidIsolatedOrigin check.  But prior to seeing a user
gesture, SiteInstanceImpl::SetSiteInfoInternal() calls
AddIsolatedOriginForBrowsingInstance directly, gated by
site_info_.does_site_request_dedicated_process_for_coop(),and nothing
leading up to this path checks IsValidIsolatedOrigin.  This CL fixes
that by adding a check for IsValidIsolatedOrigin in
NavigationRequest::ShouldRequestSiteIsolationForCOOP(), which is
where the COOP isolation plumbing starts.

Bug: 1276155
Change-Id: I465ce9cd99e2f45d306bf0031f9e4f0174f5b1a9
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3313961
Reviewed-by: Ɓukasz Anforowicz <lukasza@chromium.org>
Reviewed-by: Charlie Reis <creis@chromium.org>
Commit-Queue: Alex Moshchuk <alexmos@chromium.org>
Cr-Commit-Position: refs/heads/main@{#948697}
2 files changed
tree: cae2aa9db24ccb76de90123b2816b250dea9987d
  1. android_webview/
  2. apps/
  3. ash/
  4. base/
  5. build/
  6. build_overrides/
  7. buildtools/
  8. cc/
  9. chrome/
  10. chromecast/
  11. chromeos/
  12. cloud_print/
  13. codelabs/
  14. components/
  15. content/
  16. courgette/
  17. crypto/
  18. dbus/
  19. device/
  20. docs/
  21. extensions/
  22. fuchsia/
  23. gin/
  24. google_apis/
  25. google_update/
  26. gpu/
  27. headless/
  28. infra/
  29. ios/
  30. ipc/
  31. jingle/
  32. media/
  33. mojo/
  34. native_client_sdk/
  35. net/
  36. pdf/
  37. ppapi/
  38. printing/
  39. remoting/
  40. rlz/
  41. sandbox/
  42. services/
  43. skia/
  44. sql/
  45. storage/
  46. styleguide/
  47. testing/
  48. third_party/
  49. tools/
  50. ui/
  51. url/
  52. weblayer/
  53. .clang-format
  54. .clang-tidy
  55. .eslintrc.js
  56. .git-blame-ignore-revs
  57. .gitattributes
  58. .gitignore
  59. .gn
  60. .mailmap
  61. .rustfmt.toml
  62. .vpython
  63. .vpython3
  64. .yapfignore
  65. AUTHORS
  66. BUILD.gn
  67. CODE_OF_CONDUCT.md
  68. codereview.settings
  69. DEPS
  70. DIR_METADATA
  71. ENG_REVIEW_OWNERS
  72. LICENSE
  73. LICENSE.chromium_os
  74. OWNERS
  75. PRESUBMIT.py
  76. PRESUBMIT_test.py
  77. PRESUBMIT_test_mocks.py
  78. README.md
  79. WATCHLISTS
README.md

Logo Chromium

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.

The project's web site is https://www.chromium.org.

To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.

Documentation in the source is rooted in docs/README.md.

Learn how to Get Around the Chromium Source Code Directory Structure .

For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.

If you found a bug, please file it at https://crbug.com/new.